Vendor onboarding is the paperwork nobody wants to do, and the exact moment fraud gets in.
A finance team receives a W-9, a voided check, and an email confirming the wire instructions. They enter the routing and account number into their ERP. The record is set. Every future invoice from that vendor pays to those numbers, often for years, with no re-verification. If any of the three documents was forged at onboarding, every payment from that point forward is stolen from the first invoice.
Where the process breaks down
- The W-9 has no cryptographic signature. It is a PDF form.
- The voided check is a low-resolution image, trivially spoofable.
- The confirmation email arrives from whichever address the sender chose.
- Once entered into the ERP, the numbers are treated as trusted and are almost never re-verified.
The compounding problem
Because most companies only verify at onboarding, the trust decision made in those five minutes compounds across the entire vendor relationship. A single unverified onboarding can leak hundreds of thousands of dollars over a multi-year contract before anyone notices the payments landing at the wrong destination.
The fix is not more paperwork at onboarding. It is a verifiable, revocable channel for bank detail exchange, one where the vendor identity and the account details are cryptographically bound, and the record can be re-verified on every payment without asking anyone to fill in another form.
Sources
- AFP Payments Fraud & Control Survey
- Association of Certified Fraud Examiners, Report to the Nations




